Many web agencies are familiar with this scenario: while a site is being built, the agency is taking accessibility best practices into account. The text has sufficient color contrast, descriptive link text is used, forms have proper labels, and all images have alternative text. Six months after launch, the client uploads a blog post on their own – the text is light gray on a slightly darker gray background, there is no alternative text, and the headings are a mess. The same thing can happen with privacy – if a client changes their privacy practices, or even their business, this can affect their Privacy Policy, Cookie Policy, Cookie Consent Tool, and their compliance requirements. This is why it’s so important for website owners to keep privacy in mind when making changes to their website, practices, or business. In this article, we will review common changes and scenarios and how they may impact website privacy compliance obligations.
Example Change 1: Doing Business in New Areas
Let’s take the example of a car wash that only has locations, and thus does business, in Utah. Their business has been so successful that they are opening up a new location in Nevada. They have a website where customers can contact them and book detailing services. As they are now collecting the personal information of residents of Nevada and doing business there, Nevada Revised Statutes Chapter 603A (Nevada’s privacy law) now applies to them.
Due to this change, they need to ensure that their Privacy Policy is updated to contain the disclosures required by this law, such as whether they sell personal information. Website owners that do business in new areas, ship to new areas, offer goods or services in new areas, or seek out customers in new areas (e.g. through ads) should be aware of the fact that these changes may subject them to new privacy laws.
Example Change 2: New Purposes for Processing Personal Information
In our second example, let’s take a flower shop that has a contact form on their website. Historically, the personal information submitted through the form (name, email, and phone number) has been used only to respond to customer inquiries. However, the business owner decides that they now want to use the phone numbers to send SMS messages regarding promotions at their shop.
This change affects the website’s privacy compliance in the following ways:
- Consent: since individuals who previously submitted the contact form did not consent to receiving marketing SMS messages, they will need to provide new consent for this new purpose before the business can text them;
- Form updates: the form will need to be updated to allow individuals to opt in and consent to receiving SMS messages;
- Privacy Policy updates: the Privacy Policy will need to be updated to reflect the fact that phone numbers will be used for SMS messages and include terms regarding that messaging such as how frequently messages are sent, what types of messages are sent, and how to opt out, amongst other disclosures;
- Process: the website owner will need to update their processes to ensure that people who opt out of SMS messages do not receive such messages again.
Example Change 3: New Forms are Added
When a website is initially launched for a new business, the business owner may not yet be fully aware of all of the ways that they could use their website. For example, to start, they may just have a contact form. However, as their business grows, they may want to add a form for website visitors to sign up for email marketing or for individuals to apply for a job. Because there has been a new form added to the website, the website owner needs to update their Privacy Policy to list the personal information that is being collected by those forms, how it is being used, and who it is being shared with.
Example Change 4: New Trackers are Added
As a business grows, the website owner may choose to add additional trackers such as Google Analytics, Hotjar, LinkedIn Insights or Meta Pixel to run advertisements or see how people are using their website so that they can make improvements. When new trackers are added, the following updates need to be made:
- Consent Tool: if the website did not have a Consent Tool prior to the changes as there were no trackers or cookies set by the website, it will need to obtain one now as the website needs to get permission from the website visitor before the visitor is tracked through these tools. If there was already a Consent Tool on the website, the Consent Tool will need to be updated to include these new trackers and tested to ensure that it properly stops these trackers from firing until the user provides their consent;
- Cookie Policy: the Cookie Policy will need to be updated to include these new trackers;
- Privacy Policy: the Privacy Policy will need to be updated to reflect the fact that new personal information is being collected, how it is being used, and who it is being shared with;
Example Change 5: Sharing Personal Information with New Third Parties
While many business owners vehemently claim that they do not share personal information with third parties, it’s almost impossible to have a modern website without sharing personal information. For example, when a contact form is submitted, the information from the form is sent to the website owner via email, thereby sharing that personal information with the email service provider. Or, when an email marketing vendor such as MailChimp or ConstantContact is used, that personal information is shared with them as well.
In this example, a business owner has a contact form where people can inquire about their services. The business owner is receiving a lot of leads and needs a better way to manage them so he decides to use a customer management system, HubSpot, to track leads and where they are in the sales cycle. In this example, the business owner needs to update their Privacy Policy to reflect the fact that personal information is now being shared with the customer management system.
Example Change 6: Changes to Business Structure or Information
When a business is setting up their Privacy Policy or Cookie Policy, they will have to list their business name, the type of legal entity it is (e.g., Corporation), their address, phone number, contact information, and who should be contacted for privacy questions. As businesses change and evolve, this information may change. For example, a business may move to a new office, existing staff may leave or change roles, a DPO may be hired, or a phone number or email may change. When these items change, a business will need to update their policies to reflect their new information.
What Should Web Agencies do About This?
As you can see from the above, multiple seemingly minor changes can have a great impact on website privacy compliance. If you build websites for clients, you may be wondering, “what should I be doing about this?” Here is what you should do:
- Step 1: Ensure that your clients understand and have signed off on the fact that website compliance is their responsibility and not yours. This should be done in writing and should inform the client that they are responsible for ensuring that their website complies with all applicable privacy laws. This can be easily achieved through a Website Policies Waiver. This way, you have it documented that the client is responsible for getting their privacy compliance set up initially and for keeping it up to date.
- Step 2: Inform the client that if they make changes to their website, that they need to consider privacy compliance and make appropriate changes to their policies, consent tool, and practices. This does not have to be more complicated than this simple statement since the client is the one that is responsible for their compliance and thus it is up to them to remember this fact and take the appropriate steps to make updates and ensure that they are compliant.